| 2025 | SIGCSE | Strengthening Workforce Education: Excellence in Programming Securely (SWEEPS). | Deborah Kariuki, Ida Ngambeki, Jun Dai, Matt Bishop, Xiaoyan Sun, Melissa Dark, Jenny Daugherty, Alex Lowrie, Markus Geissler, Phillip Nico, Arshad Noor |
| 2025 | SIGCSE | Case Study 2: Mapping between an E-Voting Curriculum and the DHS/NSA CAE Knowledge Units. | Edwin Antonio Sanchez, Muwei Zheng, Matt Bishop, Xukai Zou |
| 2023 | SIGCSE | Validation of a Secure Programming Concept Inventory. | Ida Ngambeki, Matt Bishop, Jun Dai, Phillip Nico |
| 2023 | SIGCSE | Case Study: Mapping an E-Voting Based Curriculum to CSEC2017. | Muwei Zheng, Nathan Swearingen, Steven Mills, Croix Gyurek, Matt Bishop, Xukai Zou |
| 2022 | NSPW | Autonomous Vehicle Security: Composing Attack, Defense, and Policy Surfaces. | Michael Clifford, Miriam Heller, Karl N. Levitt, Matt Bishop |
| 2020 | NSPW | Trust-Based Security; Or, Trust Considered Harmful. | Abe Singer, Matt Bishop |
| 2020 | WISE | Education for the Multifaith Community of Cybersecurity. | Steven Furnell, Matt Bishop |
| 2019 | UIC | Design Patterns for Compensating Controls for Securing Financial Sessions. | Marc J. Dupuis, Camelia Bejan, Matt Bishop, Scott David, Brent Lagesse |
| 2018 | FIE | Concept Inventories in Cybersecurity Education: An Example from Secure Programming. | Ida Ngambeki, Phillip Nico, Jun Dai, Matt Bishop |
| 2018 | NSPW | Augmenting Machine Learning with Argumentation. | Matt Bishop, Carrie Gates, Karl N. Levitt |
| 2018 | SIGCSE | Special Session: Joint Task Force on Cybersecurity Education. | Diana L. Burley, Matt Bishop, Siddharth Kaza, David S. Gibson, Scott Buck, Allen Parrish, Herb Mattord |
| 2017 | INFOCOM | LeakSemantic: Identifying abnormal sensitive network transmissions in mobile applications. | Hao Fu, Zizhan Zheng, Somdutta Bose, Matt Bishop, Prasant Mohapatra |
| 2017 | NSPW | A Model of Owner Controlled, Full-Provenance, Non-Persistent, High-Availability Information Sharing. | Sean Peisert, Matt Bishop, Edward B. Talbot |
| 2017 | SIGCSE | ACM Joint Task Force on Cybersecurity Education. | Diana L. Burley, Matt Bishop, Siddharth Kaza, David S. Gibson, Elizabeth K. Hawthorne, Scott Buck |
| 2016 | ISSRE | Bear: A Framework for Understanding Application Sensitivity to OS (Mis) Behavior. | Ruimin Sun, Andrew Lee, Aokun Chen, Donald E. Porter, Matt Bishop, Daniela Oliveira |
| 2016 | NSPW | I'm not sure if we're okay: uncertainty for attackers and defenders. | Mark E. Fioravanti II, Matt Bishop, Richard Ford |
| 2016 | SIGCSE | Special Session: ACM Joint Task Force on Cyber Education. | Diana L. Burley, Matt Bishop, Elizabeth K. Hawthorne, Siddharth Kaza, Scott Buck, Lynn Futcher |
| 2016 | SP | Is Anybody Home? Inferring Activity From Smart Home Network Traffic. | Bogdan Copos, Karl N. Levitt, Matt Bishop, Jeff Rowe |
| 2015 | HotOS | The Case for Less Predictable Operating System Behavior. | Ruimin Sun, Donald E. Porter, Daniela Oliveira, Matt Bishop |
| 2014 | SP | Insider Threat Identification by Process Analysis. | Matt Bishop, Heather M. Conboy, Huong Phan, Borislava I. Simidchieva, George S. Avrunin, Lori A. Clarke, Leon J. Osterweil, Sean Peisert |
| 2014 | SP | Insider Attack Identification and Prevention Using a Declarative Approach. | Anandarup Sarkar, Sven Khler, Sean Riddle, Bertram Ludscher, Matt Bishop |
| 2013 | NSPW | Information behaving badly. | Julie Boxwell Ard, Matt Bishop, Carrie Gates, Michael Xin Sun |
| 2013 | NSPW | Forgive and forget: return to obscurity. | Matt Bishop, Emily Rine Butler, Kevin R. B. Butler, Carrie Gates, Steven Greenspan |
| 2013 | SIGCSE | Introducing secure coding in CS0 and CS1 (abstract only). | Matt Bishop, Blair Taylor, Elizabeth K. Hawthorne, Diana L. Burley, Siddharth Kaza |
| 2013 | SIGCSE | Teaching secure coding: the myths and the realities. | Blair Taylor, Matt Bishop, Elizabeth K. Hawthorne, Kara L. Nance |
| 2012 | NSPW | Turtles all the way down: a clean-slate, ground-up, first-principles approach to secure systems. | Sean Peisert, Edward B. Talbot, Matt Bishop |
| 2012 | SIGCSE | Teaching secure coding: report from summit on education in secure software. | Blair Taylor, Matt Bishop, Diana L. Burley, Steve Cooper, Ronald C. Dodge, Robert C. Seacord |
| 2011 | NSPW | Resilience is more than availability. | Matt Bishop, Marco M. Carvalho, Richard Ford, Liam M. Mayron |
| 2010 | NSPW | Relationships and data sanitization: a study in scarlet. | Matt Bishop, Justin Cummins, Sean Peisert, Anhad Singh, Bhume Bhumiratana, Deborah A. Agarwal, Deborah A. Frincke, Michael A. Hogarth |
| 2010 | SP | Reflections on the 30th Anniversary of the IEEE Symposium on Security and Privacy. | Peter G. Neumann, Matt Bishop, Sean Peisert, Marv Schaefer |
| 2010 | SecureComm | Hidden Markov Models for Automated Protocol Learning. | Sean Whalen, Matt Bishop, James P. Crutchfield |
| 2009 | ACSAC | Reflections on UNIX Vulnerabilities. | Matt Bishop |
| 2009 | NSPW | The sisterhood of the traveling packets. | Matt Bishop, Carrie Gates, Jeffrey Hunker |
| 2009 | NSPW | Quis Custodiet ipsos Custodes?: a new paradigm for analyzing security paradigms with appreciation to the Roman poet Juvenal. | Sean Peisert, Matt Bishop, Laura Corriss, Steven J. Greenwald |
| 2008 | NSPW | We have met the enemy and he is us. | Matt Bishop, Sophie Engle, Sean Peisert, Sean Whalen, Carrie Gates |
| 2008 | WETICE | Twelfth Securities Technologies (ST) Workshop Report. | David P. Gilliam, Matt Bishop |
| 2007 | RAID | Cost-Sensitive Intrusion Responses for Mobile Ad Hoc Networks. | Shiau-Huey Wang, Chinyang Henry Tseng, Karl N. Levitt, Matt Bishop |
| 2007 | WETICE | ST Workshop Final Report. | David P. Gilliam, Matt Bishop, Y. V. Ramana Reddy |
| 2006 | DIMVA | Using Type Qualifiers to Analyze Untrusted Integers and Detecting Security Flaws in C Programs. | Ebrima N. Ceesay, Jingmin Zhou, Michael Gertz, Karl N. Levitt, Matt Bishop |
| 2006 | NSPW | Sanitization models and their limitations. | Rick Crawford, Matt Bishop, Bhume Bhumiratana, Lisa Clark, Karl N. Levitt |
| 2006 | NSPW | Inconsistency in deception for defense. | Vicentiu Neagoe, Matt Bishop |
| 2006 | WETICE | Some Problems in Sanitizing Network Data. | Matt Bishop, Rick Crawford, Bhume Bhumiratana, Lisa Clark, Karl N. Levitt |
| 2006 | WETICE | Eleventh Securities Technologies (ST) Workshop Report. | David P. Gilliam, Matt Bishop |
| 2006 | WETICE | Security Verification Techniques Applied to PatchLink COTS Software. | David P. Gilliam, John D. Powell, Matt Bishop, Chris Andrew, Sameer Jog |
| 2005 | ACSAC | Verify Results of Network Intrusion Alerts Using Lightweight Protocol Analysis. | Jingmin Zhou, Adam J. Carlson, Matt Bishop |
| 2005 | NSPW | The insider problem revisited. | Matt Bishop |
| 2005 | NSPW | Position: "insider" is relative. | Matt Bishop |
| 2005 | NSPW | Principles-driven forensic analysis. | Sean Peisert, Sidney Karin, Matt Bishop, Keith Marzullo |
| 2005 | WETICE | Application of Lightweight Formal Methods to Software Security. | David P. Gilliam, John D. Powell, Matt Bishop |
| 2004 | WETICE | How to Sanitize Data. | Matt Bishop, Bhume Bhumiratana, Rick Crawford, Karl N. Levitt |
| 2003 | ACSAC | Miracle Cures and Toner Cartridges: Finding Solutions to the Spam Problem. | Michael Clifford, Daniel Faigin, Matt Bishop, Tasneem G. Brutch |
| 2003 | NDSS | Testing C Programs for Buffer Overflow Vulnerabilities. | Eric Haugh, Matt Bishop |
| 2003 | WETICE | Software Security Checklist for the Software Life Cycle. | David P. Gilliam, Thomas L. Wolfe, Joseph S. Sherif, Matt Bishop |
| 2003 | SEW | Addressing Software Security and Mitigations in the Life Cycle. | David P. Gilliam, John D. Powell, Eric Haugh, Matt Bishop |
| 2001 | ACSAC | How Useful is Software Fault Injection for Evaluating the Security of COTS Products? | Matt Bishop, Anup K. Ghosh, James A. Whittaker |
| 2001 | WETICE | Development of a Software Security Assessment Instrument to Reduce Software Security Risk. | David P. Gilliam, John C. Kelly, John D. Powell, Matt Bishop |
| 2000 | SP | Using Conservation of Flow as a Security Mechanism in Network Protocols. | John R. Hughes, Tuomas Aura, Matt Bishop |
| 2000 | WETICE | Reducing Software Security Risk through an Integrated Approach. | David P. Gilliam, John C. Kelly, Matt Bishop |
| 1999 | RAID | Vulnerability Analysis: An Extended Abstract. | Matt Bishop |
| 1998 | ACSAC | The Solar Trust Model: Authentication Without Limitation. | Michael Clifford, C. Lavine, Matt Bishop |
| 1993 | SEC | Teaching Computer Security. | Matt Bishop |
| 1991 | USENIX | An Authentication Mechanism for USENET. | Matt Bishop |
| 1990 | ACSAC | A security analysis of the NTP protocol version 2. | Matt Bishop |
| 1989 | ACSAC | A model of security monitoring. | Matt Bishop |
| 1989 | SC | UNIX security in a supercomputing environment. | Matt Bishop |
| 1981 | SOSP | Hierarchical Take-Grant Protection Systems. | Matt Bishop |
| 1979 | SOSP | The Transfer of Information and Authority in a Protection System. | Matt Bishop, Lawrence Snyder |